Intruder Sat Inside Thai Broadband Giant 3BB, Using Off-the-Shelf Admin Tool to Stay Hidden
A hacker held remote control of internal machines at one of Thailand's biggest internet providers by piggybacking on MeshCentral, a legitimate IT management tool, according to researchers at Hunt.io.

Key points
- An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, according to threat intelligence firm Hunt.io.
- The intruder held remote control of internal machines using MeshCentral, a legitimate remote-management tool, rather than custom malware.
- Hunt.io found the activity by examining a server the attacker left open on the public internet, which held their tools and a target list.
- The exposed server pointed to interest in subscriber credentials, the usernames and passwords 3BB customers use to log in.
- 3BB has not publicly confirmed the intrusion or said whether customer data was taken.
An unknown hacker was quietly living inside the network of 3BB, one of Thailand's biggest home internet providers, running the place with an IT tool the company's own administrators would recognise.
That's the finding from Hunt.io, a threat intelligence firm that scans the internet for servers criminals forget to lock down. The company said, in reporting picked up by The Hacker News, that it stumbled on one such server belonging to the intruder. On it sat the attacker's toolkit and a list of intended targets. Hunt.io has been a productive source of disclosures: we've covered the firm's work four times in the past 90 days, including a July intrusion against Thailand's Finance Ministry that shares the same regional victim profile.
The tool at the centre of the story is MeshCentral, a free, open-source program used by legitimate IT departments to manage computers from a distance. Think of it as helpdesk software, the kind that lets a technician take over your screen and fix a problem remotely, only here it was installed by someone who had no right to be there.
Who is behind it?
Hunt.io hasn't named a group. The researchers describe an attacker rather than a known ransomware crew or state-linked outfit, and there's no public claim of responsibility, no leak-site listing, no ransom demand.
What the exposed server does show is intent. It contained tooling and a target list pointing at 3BB's systems, including material useful for reaching subscriber credentials. Those are the usernames and passwords ordinary customers use to sign in.
How did the attacker get in?
The public reporting doesn't say. Hunt.io's window into the operation came from the attacker's own infrastructure, not from 3BB's internal logs, so the initial access method isn't documented.
What's clear is the technique used to stay in. By installing MeshCentral, the intruder blended into normal IT activity. Security teams scanning for obvious malware would see a management agent that, on paper, belongs there. The industry calls this living off the land: using tools the network already trusts instead of importing suspicious ones.
Should 3BB customers be worried?
Possibly, and it costs nothing to act as if the answer is yes. 3BB hasn't confirmed the intrusion or said whether any subscriber data was taken. The target list on the attacker's server suggests customer credentials were of interest, which is reason enough to act.
If you're a 3BB customer, change your account password now, and change it on any other site where you reused it. Turn on two-step login, where the service asks for a code from your phone alongside a password, wherever it's offered. Be wary of calls or messages claiming to be from 3BB and asking you to confirm details or click a link.
The wider pattern
Attackers reaching for legitimate remote-management software is routine now. MeshCentral and AnyDesk keep showing up in intrusion reports because they solve the same problem for a criminal that they solve for a sysadmin: durable, quiet remote access that doesn't trip signature-based detection.
The interesting detail here isn't the tool. It's the exposed server. Operators who forget to lock down their own infrastructure are how a lot of these stories break, and it's why Hunt.io keeps surfacing intrusions the victims haven't yet disclosed. Expect more of 3BB's story to emerge only when, and if, the company files something formal.



